U.S. Cybersecurity Agency Warns of Actively Exploited Adobe Acrobat Reader Vulnerability

11/10/2023 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a high-severity flaw in Adobe Acrobat Reader to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Tracked as CVE-2023-21608 (CVSS

Take an Offensive Approach to Password Security by Continuously Monitoring for Breached Passwords

11/10/2023 0 Comments 0 tags

Passwords are at the core of securing access to an organization’s data. However, they also come with security vulnerabilities that stem from their inconvenience. With a growing list of credentials

Microsoft Warns of Nation-State Hackers Exploiting Critical Atlassian Confluence Vulnerability

11/10/2023 0 Comments 0 tags

Microsoft has linked the exploitation of a recently disclosed critical flaw in Atlassian Confluence Data Center and Server to a nation-state actor it tracks as Storm-0062 (aka DarkShadow or Oro0lxy). The tech

Microsoft Releases October 2023 Patches for 103 Flaws, Including 2 Active Exploits

11/10/2023 0 Comments 0 tags

Microsoft has released its Patch Tuesday updates for October 2023, addressing a total of 103 flaws in its software, two of which have come under active exploitation in the wild. Of the

HTTP/2 Rapid Reset Zero-Day Vulnerability Exploited to Launch Record DDoS Attacks

11/10/2023 0 Comments 0 tags

Amazon Web Services (AWS), Cloudflare, and Google on Tuesday said they took steps to mitigate record-breaking distributed denial-of-service (DDoS) attacks that relied on a novel technique called HTTP/2 Rapid Reset.

Google Adopts Passkeys as Default Sign-in Method for All Users

11/10/2023 0 Comments 0 tags

Google on Tuesday announced the ability for all users to set up passkeys by default, five months after it rolled out support for the FIDO Alliance-backed passwordless standard for Google Accounts on

New Report: Child Sexual Abuse Content and Online Risks to Children on the Rise

11/10/2023 0 Comments 0 tags

Certain online risks to children are on the rise, according to a recent report from Thorn, a technology nonprofit whose mission is to build technology to defend children from sexual

Researchers Uncover Grayling APT’s Ongoing Attack Campaign Across Industries

11/10/2023 0 Comments 0 tags

A previously undocumented threat actor of unknown provenance has been linked to a number of attacks targeting organizations in the manufacturing, IT, and biomedical sectors in Taiwan. The Symantec Threat

New Magecart Campaign Alters 404 Error Pages to Steal Shoppers’ Credit Cards

11/10/2023 0 Comments 0 tags

A sophisticated Magecart campaign has been observed manipulating websites’ default 404 error page to conceal malicious code in what’s been described as the latest evolution of the attacks. The activity, per Akamai,

libcue Library Flaw Opens GNOME Linux Systems Vulnerable to RCE Attacks

11/10/2023 0 Comments 0 tags

A new security flaw has been disclosed in the libcue library impacting GNOME Linux systems that could be exploited to achieve remote code execution (RCE) on affected hosts. Tracked as CVE-2023-43641 (CVSS